Haystack
← Back to Jobs
Full time
Other
WC

Sr. Technology Risk Analyst

Wings Credit UnionColorado Springs, CO🇺🇸United StatesPosted Sep 21, 2026

Quick Overview

Salary
$84.0k - $98.0k/yr
Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Colorado Springs, CO, United States
Posted
18 hours ago
OWASPComplianceContinuous ImprovementHIPAAInternal AuditInternal ControlsLESSProcess ImprovementRisk AssessmentRisk Management

Job Description

Ent Credit Union and Wings Credit Union joined forces in January 2026. This merger means more opportunities, expanded resources, and a shared commitment to delivering exceptional member service. Together, we become more - empowering members, communities, and teams through a bold, unified future. Both organizations bring a strong legacy of member satisfaction, operational excellence, financial stability, and community impact. Recognized locally and nationally as best-in-class financial institutions and employers of choice, each is known for its commitment to financial well-being and philanthropic leadership. Join us during this transformative time and be part of shaping the future of banking! To learn more about the merger, click here.

The Senior Technology Risk Analyst plays a key role in helping Wings strengthen and mature its Technology Risk Management program. This position partners closely with Information Technology, Information Security, and business leaders across the organization to identify, assess, manage, and monitor technology risks while supporting the effectiveness of internal controls and risk management practices.

This role combines risk advisory, process improvement, and stakeholder partnership responsibilities, providing the opportunity to influence decision-making, strengthen organizational resilience, and support a culture of proactive risk management. The Senior Technology Risk Analyst serves as a trusted partner to business and technology teams by helping identify practical solutions, drive remediation efforts, and improve risk awareness across the organization.

The ideal candidate brings a strong foundation in technology risk management along with the ability to build relationships, navigate complex situations, and balance risk mitigation with business objectives in a collaborative and evolving environment.

 

Proposed Essential Functions

Technology Risk Assessment & Advisory

• Partner with Information Technology, Information Security, and business stakeholders to identify, assess, document, and monitor technology risks, controls, and risk mitigation activities.

• Facilitate process walkthroughs and risk assessments to evaluate the effectiveness of key technology processes and controls.

• Develop and maintain risk and control documentation, including process narratives, risk and control matrices (RACMs), and supporting evidence within Wings' Governance, Risk, and Compliance (GRC) platform.

• Identify control weaknesses, emerging risks, and process improvement opportunities while providing practical recommendations to business and technology partners.

• Support stakeholders in evaluating residual risk and determining appropriate mitigation strategies.

 

Risk Governance & Program Maturity

• Support the ongoing development and maturity of Wings' Technology Risk Management program through continuous improvement initiatives and risk management best practices.

• Partner with stakeholders to strengthen risk identification, issue management, remediation planning, and control monitoring activities.

• Assist business and technology teams in developing procedures, reporting, training, and documentation that support effective risk management practices.

• Promote consistency and accountability in technology risk assessment and control ownership processes across the organization.

• Leverage industry frameworks, regulatory guidance, and organizational priorities to enhance program effectiveness.

 

Stakeholder Partnership & Risk Consultation

• Build strong working relationships across Information Technology, Information Security, Risk Management, Internal Audit, and business teams.

• Provide guidance and consultation on technology risk matters while balancing regulatory expectations, operational needs, and business objectives.

• Facilitate productive discussions regarding risk acceptance, remediation priorities, and control improvements.

• Partner with leaders to ensure identified risks and issues are communicated appropriately and addressed in a timely manner.

• Serve as a trusted resource for technology risk management concepts, practices, and emerging industry trends.

 

Project Leadership & Execution

• Manage multiple risk management initiatives, assessments, and advisory activities while ensuring timelines, quality standards, and deliverables are achieved.

• Monitor project progress, identify potential risks to project success, and escalate concerns as appropriate.

• Support and mentor less experienced team members by sharing knowledge, providing guidance, and promoting best practices.

• Contribute to team planning efforts and help drive execution of department priorities and strategic objectives.

 

Continuous Improvement & Professional Development

• Stay informed of technology risk, cybersecurity, regulatory, and financial services industry developments.

• Identify opportunities to improve processes, reporting, workflows, and risk management practices.

• Contribute to a culture of learning, collaboration, and continuous improvement.

• Participate in training and development activities to maintain and expand professional knowledge and expertise.

Bank Secrecy Act

• Remain knowledgeable of and adhere to Wings policies, procedures, and regulations related to the Bank Secrecy Act.

 

Minimum Formal Qualifications for this Position:

  • Bachelor's Degree In Risk, Information Technology, Computer Science, Business Administration, Finance, Accounting, or another related field. preferred
  • 5+ years' of experience in a financial institution performing compliance, testing, monitoring, or similar risk management activities. Required
  • 3+ years' experience in heightened expectations regulatory environment. preferred

Technical or Specialized Knowledge/Skills:

  • Verbal, written, and interpersonal skills to interact with associates at all levels of responsibility, along with the ability to communicate with tact and diplomacy.
  • Problem-solving and analytical skills with the ability to quickly digest issues/problems encountered and recommend an appropriate solution.
  • Knowledge of risk management principles.
  • Presentation skills.
  • Ability to proactively identify potential concerns and follows up to resolve issues.
  • Ability to be detail oriented with strong critical thinking, analytical skills and effective analysis of data.
  • Technical knowledge of insurance forms and industry best practices.
  • Understanding of technology processes (i.e. Change management, security operations, technology operations, and application controls).
  • Knowledge of IT systems/data security controls including but not limited to firewalls, IPS/IDS, SIEM, and other security device platforms.
  • Understanding of diverse security practices along with IT risk management concepts and applies them effectively when developing security solutions.
  • Ability to assist in Maintaining and testing Ent's business continuity program by Evaluating BCPs to Enterprise BCP goals and advising business leaders on identifying critical functions and needs.
  • Ability to assist with the design and outline of BCP goals, objectives, and scope for BCPs and Crisis Management.
  • Knowledge of regulations and best practices for technical deployments specific to the financial industry, disaster recovery/business resumption technique, secure coding and application design, packet analysis, and forensic tools.
  • Knowledge of industry regulations and best practices such as PCI, GLBA, FFIEC, NIST, ISO 27000, HIPAA, OWASP, SSAE 18, SOC2, and the Cloud Security Alliance.
  • Organizational skills and attention to detail.
  • Ability to multi-task and adhere to sensitive deadlines.
  • Ability to develop and maintain relationships with Information Technology and Security teams.

Certifications Required:

  • Certified in Risk and Information Systems Control (CRISC) within 1 Year required
  • Certified Information System Security Professional (CISSP) within 1 Year required
  • Certified Information Systems Auditor (CISA) within 1 Year required

 

PAY RANGE: $83,969 to $97,968 Annually ($40 to $47 per Hour) + 15% annual target bonus.
Final compensation for this position will be determined by various factors such as relevant work experience, specific skills and competencies, education, certifications, location and internal pay equity.
BENEFITS:

  • Generous 401(k) match
  • 401k Discretionary Profit Sharing
  • Health Insurance
  • Dental Insurance
  • Vision Insurance
  • Life Insurance
  • Short Term and Long Term Disability
  • Health Savings Account with company contribution
  • Employee Assistance Program
  • Paid Vacation, Sick, Floating Holidays and Volunteer Time Off
  • Paid Holidays
  • Tuition Reimbursement
  • Paid Parental Leave
    We anticipate this position to close on 09/28/26. Please submit your application at your earliest convenience to be considered.
    Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.